Gli agenti autenticati con token Bearer possono leggere today/pipeline e annotare attività, con host MCP allineati a quelli di produzione. Co-authored-by: Cursor <cursoragent@cursor.com>
25 lines
746 B
Ruby
25 lines
746 B
Ruby
require "test_helper"
|
|
|
|
class ApiTokenTest < ActiveSupport::TestCase
|
|
test "issue returns plaintext once and authenticates" do
|
|
token = ApiToken.issue!(user: users(:marco), name: "Cursor")
|
|
assert token.plaintext.start_with?("crm_")
|
|
assert_equal token.plaintext[0, 8], token.token_prefix
|
|
|
|
found = ApiToken.authenticate(token.plaintext)
|
|
assert_equal token.id, found.id
|
|
end
|
|
|
|
test "revoked or inactive user does not authenticate" do
|
|
token = ApiToken.issue!(user: users(:marco), name: "tmp")
|
|
raw = token.plaintext
|
|
token.revoke!
|
|
assert_nil ApiToken.authenticate(raw)
|
|
end
|
|
|
|
test "blank token does not authenticate" do
|
|
assert_nil ApiToken.authenticate(nil)
|
|
assert_nil ApiToken.authenticate("")
|
|
end
|
|
end
|